cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
414
Views
4
Helpful
2
Replies

using AAA for enable mode

WILLIAM STEGMAN
Level 4
Level 4

I used to use TACACS and ACS to enable active directory accounts to be used for enable mode. After using their AD account to ssh or telnet you would then type enable and then use your AD password. Now I don't have TACACS and need to use Radius, IAS, on a windows server. I have telnet and ssh setup to use the AD accounts, but how/can I set up the enable mode to use AD accounts?

thank you,

Bill

2 Replies 2

Jagdeep Gambhir
Level 10
Level 10

Bill,

Enable authentication was meant to function with TACACS, and when used with RADIUS it does not perform the same. As a result, the only way for you to get enable authentication to work with RADIUS would be to input the username $enab15$ into your RADIUS server and every user would need to use that password to login to enable mode.

Regards,

~JG

Do rate helpful post

bummer, thanks for the info though. I did kind of find another work around, but it brought up another problem specific to our monitoring system. It was using the privilege level 15 under the lint vty command. That may help someone else so I thought I'd post it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: